01-26-2020 08:12 PM
Hi,
I have a site-to-site VPN with one of our vendor. Since they have similar n/w with our internal network, we are using NAT in ASA. Now the vendor is moving to Azure and using the same network (local). They are replicating their servers from on premise to azure. In that case we need to create another site-to-site VPN with azure. The challenge is to configure NAT with same vendor local network. Is that possible or is there any issue wile configure NAT with same vendor local subnets. The NATed IP will be different.
Regards
Sooraj
01-26-2020 08:58 PM
Hi,
You will be fine with the different Nat IP's of the subnets behind Azure cloud. You need to do NAT at both ends of tunnel to avoid conflict.
01-26-2020 09:08 PM
Thanks Muhammad.
Currently the NAT is configured in our side (ASA side).
Also when the vendor moving this to Azure and replicating the server from onpremise, I should configure the NAT in our side (ASA), not Azure side but with a different NAT subnet. Is there any way to do it in oour side with out NAT ing in Azure side.
The current NAT is attached here. In that NET-Unit4_LAN is the vendor subnet and NET-Unit4_LAN_NAT is the NATed subnet. When the vendor moving to Azure the NET-Unit4_LAN should be the same and NET-Unit4_LAN_NAT subnet will change a different subnet. Is that possible to create a NAT while setup new site-to-site VPN with Azure.
Regards
Sooraj
01-26-2020 09:41 PM
Hi,
One of the possibilities is to get one more interface for internet. Having one more interface , you can define NAT rule in similar way which you have defined already with differented Nated Address. By this, we can avoid any NAT on azure side however they have to use ipsec tunnel with your new interface IP.
Is It possible to have one more Internet interface?
01-26-2020 10:11 PM
01-26-2020 10:17 PM
Hi,
Problem is not creating an interface, we can utilize any unused port or check the possibility of sub interfsce. Problem with new ISp connectoon, can you get one more Internet connection from ISP with static IP?
Otherwise we have only choice left to configure ipsec tunnel with NAT on both sides.
01-26-2020 11:31 PM
Hi,
Is there any other option other that creating new internet interface and NAT on both sides.
Is there any option like configuring a new NAT in our side?
Thanks
Sooraj
01-27-2020 12:00 AM - edited 01-27-2020 12:29 AM
Hi,
I don't think we can have additional option on ASA for this scenario. ASA will not allow you to create one more NAT with using same Source address, same source interface and different destination address.
How many IP's you are using for the appliance and services ? And how the migration will happen, is it going to be partial like some services will be migrated or it will be a single shot ?
If it is partial then we can do NAT for specific IP's instead of translating complete subnet which can achieve your objective.
Further, how the ASA is connected with ISP, is it connected to the Cisco Router ? If yes, then whether Router is doing NAT for public IP's or you assigned public IP directly to the ASA interface ?
01-27-2020 01:43 AM
Thanks for the mail.
They are migrating the services using Azure Site Recovery method. It might be a single shot migration and then replicating it. For some to confirm the azure services are working fine, both the on prem and azure services will be up.
The ASA is connected to ISP router (Juniper). But assigned the public IP directly to the ASA internet interface.
Regards
Sooraj
01-27-2020 05:37 AM
Hi,
That will be a challenge to keep both on-prem and cloud services to remain up at same time. Considering the situation, it seems best design will be to do a NAT on the cloud side in addition to your local ASA.
Maybe your vendor can do some help here.
01-27-2020 07:43 PM
Hi,
In simple I have two customers which I need to setup a site-to-site VPN with both customers having same local network and they can't do NAT from their end. I cannot force the customer to do NAT on their end. How to implement two NATs with same source interface and same source address in cisco ASA.
Regards
Sooraj
01-29-2020 02:55 PM
01-26-2020 09:04 PM
01-26-2020 09:17 PM
Regards
Sooraj
01-27-2020 06:34 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide